Pass
Vendor:
First CVE: Nov 9, 2022 · Active for 3 years
10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pass over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 9, 2022
3 years ago
Most Recent CVE
Nov 6, 2024
625 days ago
CVE Severity & Scoring
Pass10 CVEs
90%
10%
All CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local1 (10.0%)
Network1 (10.0%)
Unknown0 (0.0%)
Physical8 (80.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39892CRITICAL Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature. | Nov 9, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-39911MEDIUM Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass. | Dec 8, 2022 | 6.8 | 22 | NO | NO |
CVE-2023-42575MEDIUM Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting. | Dec 5, 2023 | 6.8 | 20 | NO | NO |
CVE-2023-42576MEDIUM Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler. | Dec 5, 2023 | 6.8 | 19 | NO | NO |
CVE-2023-42554MEDIUM Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication. | Nov 7, 2023 | 6.8 | 19 | NO | NO |
CVE-2023-30675MEDIUM Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed. | Jul 6, 2023 | 5.5 | 17 | NO | NO |
CVE-2022-39910MEDIUM Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device usi | Dec 8, 2022 | 4.2 | 17 | NO | NO |
CVE-2024-49405MEDIUM Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access sensitive information in a specific scenario. | Nov 6, 2024 | 4.6 | 16 | NO | NO |
CVE-2023-30677MEDIUM Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device. | Jul 6, 2023 | 4.6 | 16 | NO | NO |
CVE-2023-30676MEDIUM Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass. | Jul 6, 2023 | 4.6 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Pass
Top CWEs
Versions
No cataloged versions.